Security

security-violation error

vineeth10
New Member

Hello,

is there anyway i can genrate alert and send mail from splunk .
for eg:- if there is an security-violation error on a particular switch like err-disable state if someone tried to connect a switch or router on a access port.

or

if a stack one of the switch went down splunk should send me an alert via email to my network team.

is it possible ?

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it is possible. If you can search for it, you can alert on it. Once you've produced a search that finds the event(s) of interest, schedule it to run at some interval - every 15 minutes, for example. Then choose an alert trigger. I've found if number of events is equal to 0 works best for my searches. Mark the Send email box and fill in the addresses to which to send the alert.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...